Assuring Compliance in IT Subcontracting and Cloud Computing

被引:0
|
作者
Knolmayer, Gerhard F. [1 ]
Asprion, Petra [1 ]
机构
[1] Univ Bern, Inst Informat Syst, CH-3012 Bern, Switzerland
关键词
Outsourcing; Compliance; Frameworks; Audit; Subcontracting; Cloud Computing;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Companies and their business processes are subject to many regulations. Today's business processes are widely supported by IT systems. Therefore these systems play an important role in assuring compliance. The need to assure compliance can influence IT outsourcing decisions. We summarize some frameworks that give recommendations on assuring compliance of outsourced activities. For a service provider with many globally acting customers similar audit activities of many auditors would be time-consuming and expensive. To avoid these costs, the American Institute of Certified Public Accountants (AICPA) suggested that an auditor may provide a SAS 70 Audit Report Type II which confirms the existence and effectiveness of internal controls. Recently, the AICPA replaced the SAS 70 with the attestation standard SSAE 16. Based on frameworks and guidelines we discuss compliance issues in special cases of outsourcing relationships such as Subcontracting and Cloud Computing.
引用
收藏
页码:21 / 45
页数:25
相关论文
共 50 条
  • [21] Assessing requirements compliance scenarios in system platform subcontracting
    Regnell, Bjorn
    Olsson, Hans O.
    Mossberg, Staffan
    PRODUCT-FOCUSED SOFTWARE PROCESS IMPROVEMENT, PROCEEDINGS, 2006, 4034 : 362 - 376
  • [22] ATMOSPHERE: Adaptive, Trustworthy, Manageable, Orchestrated, Secure, Privacy-assuring, Hybrid Ecosystem for REsilient cloud computing
    Brasileiro, Francisco
    Brito, Andrey
    Blanquer, Ignacio
    2018 48TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOPS (DSN-W), 2018, : 51 - 52
  • [23] Teaching cloud computing in cloud computing
    Moravcik, Marek
    Segec, Pavel
    Uramova, Jana
    Kontsek, Martin
    2017 15TH IEEE INTERNATIONAL CONFERENCE ON EMERGING ELEARNING TECHNOLOGIES AND APPLICATIONS (ICETA 2017), 2017, : 319 - 324
  • [24] Enhancing Voltage Compliance in Distribution Network Under Cloud and Edge Computing Framework
    Zhong, Jiangxia
    Liu, Bin
    Yu, Xinghuo
    Wong, Peter
    Wang, Zeyu
    Xu, Chongchong
    Zhou, Xiaojun
    IEEE TRANSACTIONS ON CLOUD COMPUTING, 2023, 11 (02) : 1217 - 1229
  • [25] Remote Consulting for Product FMC Compliance by Means of Virtual Workspace and Cloud Computing
    Wu, Wei
    Chen, Shisheng
    Cai, Chunchao
    Xu, Yi
    2016 IEEE 16TH INTERNATIONAL CONFERENCE ON ENVIRONMENT AND ELECTRICAL ENGINEERING (EEEIC), 2016,
  • [26] Cloud Computing: Security Model Comprising Governance, Risk Management and Compliance.
    Al-Anzi, Fawaz S.
    Yadav, Sumit Kr.
    Soni, Jyoti
    2014 INTERNATIONAL CONFERENCE ON DATA MINING AND INTELLIGENT COMPUTING (ICDMIC), 2014,
  • [27] ATMOSPHERE: Adaptive, Trustworthy, Manageable, Orchestrated, Secure, Privacy-assuring, Hybrid Ecosystem for REsilient cloud computing
    Brito, Andrey
    Brasileiro, Francisco
    Blanquer, Ignacio
    Silva, Altigran
    Carvalho, Andre
    2019 9TH LATIN-AMERICAN SYMPOSIUM ON DEPENDABLE COMPUTING (LADC), 2019, : 177 - 180
  • [28] Disbanding the "Process Police": New Visions for Assuring Compliance
    Shull, Forrest
    IEEE SOFTWARE, 2012, 29 (03) : 3 - 6
  • [29] Computing Compliance
    Ciardelli, Ivano
    Cornelisse, Irma
    Groenendijk, Jeroen
    Roelofsen, Floris
    LOGIC, RATIONALITY, AND INTERACTION, PROCEEDINGS, 2009, 5834 : 55 - 65
  • [30] ASSURING A FEDERALLY REGULATED DRUG AND ALCOHOL PROGRAM IS IN COMPLIANCE
    Hearne, M. Diane
    WORKPLACE HEALTH & SAFETY, 2012, 60 (07) : 295 - 296